Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-82451

MEDIUM NVD
CVSS Score 6.1
Severity MEDIUM
Published Aug 29, 2026
Vendor unknown

Description

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.

References